CVE-2026-82588
Open5GS Transfer Endpoint namf-handler.c null pointer dereference
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such manipulation leads to null pointer dereference. The attack can be launched remotely. Upgrading to version 2.8.0 is capable of addressing this issue. The name of the patch is abf8a836564b966b5141110fc25ed413c4f17522. Upgrading the affected component is advised.
| CWE | CWE-476 CWE-404 |
| Vendor | n/a |
| Product | open5gs |
| Published | Aug 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a open5gs
Be the first to know when new medium vulnerabilities affecting n/a open5gs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / Open5GS
2.7.0 2.7.1 2.7.2 2.7.3 2.7.4 2.7.5 2.7.6 2.7.7
References
vuldb.com: https://vuldb.com/vuln/397083 vuldb.com: https://vuldb.com/vuln/397083/cti vuldb.com: https://vuldb.com/cve/CVE-2026-82588 vuldb.com: https://vuldb.com/submit/891891 github.com: https://github.com/open5gs/open5gs/issues/4397 github.com: https://github.com/open5gs/open5gs/commit/abf8a836564b966b5141110fc25ed413c4f17522 github.com: https://github.com/open5gs/open5gs/releases/tag/v2.8.0 github.com: https://github.com/open5gs/open5gs/
Credits
๐ ZiyuLin (VulDB User)